CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,812)
page 39 of 1,041| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-31877 | Cri | 0.64 | 9.8 | 0.00 | Mar 11, 2026 | Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to. This vulnerability is fixed in… | ||
| CVE-2026-3843 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2026 | Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter… | ||
| CVE-2025-40639 | Cri | 0.64 | 9.8 | 0.00 | Mar 9, 2026 | A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount.php'. | ||
| CVE-2026-30860 | Cri | 0.64 | 9.9 | 0.01 | Mar 7, 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's database query functionality. The validation system fails to recursively inspect… | ||
| CVE-2026-28785 | Cri | 0.64 | 9.8 | 0.00 | Mar 6, 2026 | Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them to read, modify, or delete sensitive financial data for all… | ||
| CVE-2026-27005 | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3, an unauthenticated attacker can inject arbitrary SQL into queries executed against databases connected to Chartbrew (MySQL,… | ||
| CVE-2026-28443 | Cri | 0.64 | 9.8 | 0.00 | Mar 5, 2026 | OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint has a SQL injection in the sort.field parameter. This issue has been patched in version 1.20.0. | ||
| CVE-2025-66944 | Cri | 0.64 | 9.8 | 0.01 | Mar 4, 2026 | SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search API endpoint | ||
| CVE-2025-66678 | Cri | 0.64 | 9.8 | 0.01 | Mar 4, 2026 | An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitrary read and write operations via a crafted request. | ||
| CVE-2025-70821 | Cri | 0.64 | 9.8 | 0.00 | Mar 3, 2026 | renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component | ||
| CVE-2026-26713 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php. | ||
| CVE-2026-26712 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php. | ||
| CVE-2026-26711 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php. | ||
| CVE-2026-26710 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php. | ||
| CVE-2026-26709 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php. | ||
| CVE-2026-26707 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php. | ||
| CVE-2026-26706 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php. | ||
| CVE-2026-26705 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php. | ||
| CVE-2026-26704 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php. | ||
| CVE-2026-26708 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php. |
- risk 0.64cvss 9.8epss 0.00
Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to. This vulnerability is fixed in…
- risk 0.64cvss 9.8epss 0.01
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter…
- risk 0.64cvss 9.8epss 0.00
A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount.php'.
- risk 0.64cvss 9.9epss 0.01
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's database query functionality. The validation system fails to recursively inspect…
- risk 0.64cvss 9.8epss 0.00
Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them to read, modify, or delete sensitive financial data for all…
- risk 0.64cvss 9.8epss 0.01
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3, an unauthenticated attacker can inject arbitrary SQL into queries executed against databases connected to Chartbrew (MySQL,…
- risk 0.64cvss 9.8epss 0.00
OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint has a SQL injection in the sort.field parameter. This issue has been patched in version 1.20.0.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search API endpoint
- risk 0.64cvss 9.8epss 0.01
An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitrary read and write operations via a crafted request.
- risk 0.64cvss 9.8epss 0.00
renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php.